Executive brief
A vulnerability in Google Chrome's developer tools (DevTools) could allow a malicious website to bypass standard navigation restrictions. By tricking a user into visiting a specially crafted webpage, an attacker could potentially force the browser to navigate to unintended locations. This issue is categorized as low severity by the developer.
Technical details
An improper input validation vulnerability (CWE-20) exists in the DevTools component of Google Chrome. The flaw stems from insufficient validation of untrusted input, which can be leveraged by a remote attacker to bypass navigation restrictions. To exploit this, an attacker would need to host a malicious HTML page and entice a user to visit it. Successful exploitation allows the attacker to trigger unauthorized navigations within the browser context. The issue is addressed in Chrome version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: disclosed